SRC
Founded in 2000, SRC Security Research & Consulting GmbH is a Bonn-based IT security consulting and certification firm serving German banking, healthcare (telematics infrastructure), and critical infrastructure clients. It is the only private EUCC certification body in Germany and holds BSI, gematik, and PCI SSC recognitions.
- Company typePrivate
- Founded2000
- HeadquartersBonn, Germany
- Headcount11–50
- GTM typeB2B
- OfferingServices
What SRC does
SRC Security Research & Consulting GmbH is a Bonn-based IT security consulting and certification firm founded in 2000, originating from the German credit industry (Kreditwirtschaft). The company provides advisory consulting and accredited testing and certification services to three primary verticals: banking and financial institutions, the German healthcare sector including the telematics infrastructure, and critical infrastructure operators — with a secondary focus on payment hardware and software manufacturers. SRC holds official recognitions from BSI as a Common Criteria (ISO 15408) test laboratory, from gematik as an authorized security assessor body, from the PCI Security Standards Council as an assessor across PCI DSS, PTS, P2PE, MPoC, and 3DS, and — via wholly-owned subsidiary SRC Zert GmbH & Co. KG — is the only private EUCC certification body in Germany.
The company's core technology stack centers on two proprietary test tools: SECCOS EMV flexiSim (a chip card simulator supporting SECCOS 5/6/7 operating systems with EMV, GeldKarte, and preconfigured girocard/Mastercard/Visa/JCB/TAN configurations) and SCALA Test-Tools (for testing software systems, chip cards, and terminals). SRC also contributed to the specification of SECCOS, the security operating system underlying Germany's national payment card infrastructure. Service lines span PCI DSS auditing, Common Criteria evaluations, gematik approval processes, TR-03161/TR-03174/TR-03109 testing, PSD2 RTS certification, eIDAS conformity assessment, §8a BSIG KRITIS audits, ISO 27001 on BSI IT-Grundschutz basis, and emerging AI-related services including AIMS (AI Management System) Quick Check and LLM penetration testing launched in late 2025.
SRC operates a B2B sales-led professional services model with no public pricing, delivering bespoke consulting and testing engagements through direct enterprise relationships. Go-to-market leverages technical content marketing (blog, LinkedIn, Xing), industry events (E-world, CAST ID:SMART), regulatory body recognitions that function as a de facto customer acquisition channel, and the SRC eHealth Academy for training delivery. Revenue streams include professional services (consulting, testing, certification), training (eHealth Academy), and licensing of proprietary test tools. The company is privately held with no disclosed external investors, led by Managing Director Markus Schierack, with 11-50 employees operating primarily in the DACH region and broader EU, including long-standing cross-border engagements such as the partnership with French payment service provider Nepting SAS dating to 2014.
SRC firmographics
Firmographics- Name
- SRC
- Legal name
- SRC Security Research & Consulting GmbH
- Website
- https://src-gmbh.de
- Company type
- Private
- Founded year
- 2000
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Founded in 2000, SRC Security Research & Consulting GmbH is a Bonn-based IT security consulting and certification firm serving German banking, healthcare (telematics infrastructure), and critical infrastructure clients. It is the only private EUCC certification body in Germany and holds BSI, gematik, and PCI SSC recognitions.
- Ownership category
- akta.pro rank
SRC industry classification
Industry- Product category
- IT Security Testing & Certification Services
- NAICS
- Management Consulting Services (54161), Testing Laboratories and Services (541380), Management, Scientific, and Technical Consulting Services (5416), Scientific Research and Development Services (5417)
- SIC
- Services-Management Consulting Services (8742), Services-Testing Laboratories (8734), Services-Engineering Services (8711)
- akta.pro primary industry
- Compliance Technology, GRC Platforms & Controls Automation Advisory (BPAHAFAO)
- akta.pro secondary industries
- Governance, Risk & Compliance (GRC) Platforms (BPAEAPAA), IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK), Privacy, Consent & Data Protection Management (BPAEAPAF)
Keywords
Where SRC is headquartered
LocationHeadquarters
- HQ city
- Bonn
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
SRC business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Security Consulting Services: Advisory and consulting engagements covering IT security strategy, compliance with regulatory frameworks (BAIT, PSD2, NIS2, DORA, eIDAS), and technical implementation support for financial institutions, healthcare organizations, and payment service providers.
- Testing and Certification Services: Laboratory testing and certification services including Common Criteria evaluations, TR-03161 testing, PCI DSS auditing, PCI PTS/MPoC/P2PE/3DS certifications, gematik approval processes, and EUCC conformity assessments.
- Training and Academy Services: SRC eHealth Academy provides structured training programs, in-house seminars, webinars, and briefings on telematics infrastructure, eHealth IT security, and regulatory compliance topics.
- Test Tools and Software Licenses: Sale and licensing of proprietary test tools including SECCOS EMV flexiSim chip card simulator and SCALA test tools for software systems, chip cards, and terminals.
Go-to-market motion1 record
Distribution channels2 records
Marketing channels6 records
SRC product offering
Product offeringCore offering
SRC Security Research & Consulting GmbH is a Bonn-based IT security services firm providing accredited testing, certification, and advisory services for payment transactions, healthcare IT (telematics infrastructure), and financial sector compliance. The company operates BSI- and gematik-recognized test laboratories, performs Common Criteria evaluations, PCI DSS audits, TR-03161 testing, and EUCC certifications, while also licensing proprietary test tools (SECCOS EMV flexiSim and SCALA Test-Tools) used by card and terminal developers.
Product overview
SRC Security Research & Consulting GmbH is a security consulting and certification company offering a comprehensive portfolio of IT security services. The core offering centers on two proprietary testing platforms: SCALA Test-Tools for testing software systems, chip cards, and terminals; and SECCOS EMV flexiSim, a software simulator of German credit industry smart cards for card terminal and host system testing. Complementing these are extensive certification and audit services including PCI DSS auditing, Common Criteria evaluations, gematik approval for healthcare components, PSD2 RTS certification, eIDAS conformity assessment, and BSI Technical Guideline testing (TR-03161, TR-03174, TR-03109). The company provides specialized consulting for banking compliance (BAIT, TIBER-DE, DORA), project management for complex implementations, and AI-related services through the AIMS (AI Management System) framework. The SRC eHealth Academy delivers structured training on telematics infrastructure and eHealth topics.
Differentiator
Problem solved
Functional benefit
Products and services
- SCALA Test-Tools Proprietary test tools developed by SRC for testing software systems, chip cards, and terminals, spanning transmission protocols to application layers, including test conception and execution support. Targeted at payment system developers and certification labs.
- SECCOS EMV flexiSim Software simulator of German credit industry smart cards (SECCOS 7, 6, 5) for testing card terminals and host systems, supporting EMV application, GeldKarte application, and preconfigured card setups (girocard, Mastercard, Maestro, VISA, JCB, etc.). For payment system developers and testers.
- PCI DSS Auditing Payment Card Industry Data Security Standard auditing services performed by SRC as a recognized PCI Security Standards Council security assessor, for merchants, payment service providers, and processors requiring PCI DSS compliance.
- gematik-Zulassung (Telematics Infrastructure Approval) Approval and certification services for healthcare telematics infrastructure components per gematik requirements, including security assessments of electronic patient record (ePA), e-prescription, and KIM/TIM modules. For DiGA providers and TI component vendors.
- PSD2 RTS Certification Certification services for compliance with the Payment Services Directive 2 Regulatory Technical Standards, including strong customer authentication and secure communication requirements. For banks, payment service providers, and FinTechs.
- eIDAS Conformity Assessment Conformity assessment for electronic identification and trust services under the eIDAS regulation, including qualified signature and seal creation device certification. For trust service providers and certificate authorities.
- Common Criteria Evaluations Security evaluations based on Common Criteria methodology (ISO 15408) for IT products, performed as a BSI-recognized test laboratory. For IT product vendors requiring formal certification of security properties.
- BSZ (Beschleunigte Sicherheitszertifizierung) Accelerated security certification services designed to streamline time-to-market for products requiring security certification. For vendors needing faster certification cycles.
- NESAS CCS-GI Certification Network Equipment Security Assurance Scheme (NESAS) certification for secure communication and information processing systems. For telecom and network equipment vendors.
- SRC eHealth Academy Structured training program on telematics infrastructure and eHealth covering ePA, KIM, TIM, DiGA, and IT security topics. Delivered via in-house seminars, webinars, and compact briefings. For healthcare IT professionals and management.
- AIMS Quick Check Pragmatic AI management system assessment delivered as three workshops (Kick-off and guard rails, Discovery and inventory, Analysis and roadmap) producing structured text reports on AI systems, data processing, and risks. For organizations deploying AI in regulated environments.
- LLM Penetration Testing Four-phase penetration testing service for LLM-based applications covering Business Understanding, Threat Modeling, Test Execution, and Reporting. Addresses prompt injection, uncontrolled tool execution, RAG architecture manipulation, and sensitive data leakage. For organizations deploying LLM-based systems.
- BSI TR Testing Services Testing and certification services performed according to BSI Technical Guidelines, including TR-03161 for digital health applications (DiGA), TR-03174 for financial sector applications, and TR-03109 for smart meter gateways. For regulated industries.
- Banking Compliance Consulting Consulting and advisory services for banking compliance covering BAIT, TIBER-DE, DORA, and PSD2 requirements. Delivered as recognized assessor work for BSI, PCI, and the German banking industry. For banks, credit institutions, and FinTechs.
- Electronic Payment Transactions Services Electronic payment transaction consulting and testing services spanning specification, implementation support, acceptance testing, and compliance auditing across girocard, EMV, and SEPA standards. For payment service providers, banks, and FinTechs.
Quantifiable outcome
- 11 of 43 gematik-approved security assessors in Germany are from SRC, making SRC the largest pool nationally
- +3 more outcomes
Companies that use SRC
Customer profileNamed customers4 records
Segments4 records
Ideal customer profiles4 records
SRC technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration1 record
AI capability5 records
Feature5 records
SRC partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core and minor.
- CAST e.V.coreSRC supports the CAST ID:SMART workshop (formerly Smartcard Workshop, held at Fraunhofer SIT, Darmstadt) as a member of the advisory board and presents technical contributions on identity and verification requirements. The workshop brings together technical depth, standardization, and practice in the field of digital identities, electronic wallets, ID documents, IoT, mobility, and government services.
- Bank-VerlagcoreSRC partners with Bank-Verlag (the banking industry publisher and service provider) to demonstrate how qualified electronic signatures enable fully digital processes in banking. Experts from both organizations collaborated on a video explaining complex signature process requirements and the role of certified trust services, combining SRC's security testing expertise with Bank-Verlag's position in the banking industry.
- Berlin GroupminorSRC has accompanied the Berlin Group (which creates uniform technical standards for European payment transactions) for many years as a technical partner, contributing expertise from payment roaming to SEPA and open banking interfaces. SRC's involvement in standardization efforts is part of its broader engagement in national and international standards bodies.
- gematik GmbHcoreSRC serves as an authorized security assessor body for gematik, conducting security assessments of telematics infrastructure components including the electronic patient record (ePA) and e-prescription specialist services. SRC maintains 11 of the 43 gematik-listed security assessors, the largest pool in Germany, conducting assessments in compliance with BSI and gematik security guidelines.
- SysEleven GmbHminorSRC accompanied SysEleven GmbH's ISO 27001 certification on the basis of BSI IT-Grundschutz (IT baseline protection), with SRC's colleague Randolf Skerka participating as an auditor in the certification handover ceremony in March 2025.
- Nepting SAScoreNepting SAS (founded 2012, Montpellier, France) is a payment service provider integrating multiple payment methods including Carte Bancaire, international cards, and German girocard. SRC has partnered with Nepting since 2014 covering PCI DSS certifications, software security consulting, PCI P2PE solution establishment (2020-2023), PCI PIN proof, girocard approval with security assessments and Nexo certification, PCI MPoC solution for mobile payments on COTS devices, and PCI 3DS for e-commerce authentication. The partnership provides Nepting with all certifications from a single source.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
SRC competitors and assessment
Company assessmentDirect peers
- Genua GmbH: German IT security company specializing in high-assurance network security, firewall solutions, and Common Criteria-certified products. Comparable to SRC through BSI-evaluated security products and German public sector/regulated industry client base, though more product-focused than SRC's services model.
- Bundesdruckerei GmbH: German state-affiliated secure identity and document provider deeply involved in German healthcare telematics infrastructure (ePA, eGK platform). Comparable to SRC through shared gematik ecosystem participation and electronic signature (eIDAS) certification expertise, though operates as a much larger government-linked entity.
- mgm technology partners GmbH: German GRC (Governance, Risk, Compliance) consulting firm with strong banking compliance practice covering BAIT, PSD2, and DORA. Directly competes with SRC in regulatory technology consulting for financial institutions, with similar target client base in German banks and FinTechs.
- secunet Security Networks AG: German IT security specialist providing SINA cryptography, security consulting, and telematics infrastructure components. Comparable to SRC through deep involvement in German healthcare telematics infrastructure (gematik) and Bundesamt für Sicherheit in der Informationstechnik (BSI)-certified security solutions, though more product-oriented than SRC's consulting focus.
Broad incumbents
- SGS SA: Global TIC leader with cybersecurity testing and certification practices. Comparable to SRC in offering Common Criteria evaluations and security certification services, but at much greater scale and global geographic reach across all TIC verticals.
- TÜV Rheinland: One of the world's largest testing, inspection, and certification (TIC) companies, also designated as an EUCC testing laboratory and certification body. Directly competes with SRC in Common Criteria evaluations, EUCC certification, and broader IT security testing in Germany, though operating at vastly greater scale across all TIC verticals.
- Utimaco Management Services: German cybersecurity company specializing in hardware security modules (HSMs), key management, and payment security. Overlaps with SRC in payment security domain (PCI standards, eIDAS qualified signature creation devices) and serves similar banking and government clients.
- TÜV SÜD: Global TIC incumbent with substantial cybersecurity testing and certification operations in Germany. Competes with SRC in Common Criteria evaluations, PCI assessments, and is positioned to enter EUCC certification, though operates at much broader scope across industrial and product certification.
- Bureau Veritas: Global TIC company with cybersecurity testing and certification operations, including Common Criteria evaluations. Competes with SRC in cybersecurity certification globally while operating at vastly greater scale across marine, commodities, and industrial inspection sectors.
- DEKRA: Major German TIC company with growing cybersecurity and IT security testing capabilities. Competes with SRC in certification and security assessment services, particularly in industrial and IoT security contexts, while operating across broader non-IT testing verticals.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights6 records
Customer concentration
SRC social profiles
Digital presenceSRC compliance and trust
Trust signalCompliance9 records
SRC financial estimates
Financial estimateRevenue estimate
Valuation estimate
SRC leadership team
Management profileNumber of profiles
Profiles8 records
SRC subsidiaries and ownership
Company hierarchySubsidiaries1 record
SRC funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SRC M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SRC
What does SRC do?
SRC Security Research & Consulting GmbH is a Bonn-based IT security services firm providing accredited testing, certification, and advisory services for payment transactions, healthcare IT (telematics infrastructure), and financial sector compliance. The company operates BSI- and gematik-recognized test laboratories, performs Common Criteria evaluations, PCI DSS audits, TR-03161 testing, and EUCC certifications, while also licensing proprietary test tools (SECCOS EMV flexiSim and SCALA Test-Tools) used by card and terminal developers.
Is SRC a public or private company?
SRC is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was SRC founded?
SRC was founded in 2000. It employs 11 to 50 people.
Where is SRC based?
SRC is headquartered in Bonn, Germany, in the Europe region.
How does SRC make money?
Four revenue lines are on record. Security Consulting Services are the primary driver. The others are testing and Certification Services, training and Academy Services and test Tools and Software Licenses.
Who are SRC's main competitors?
Direct peers on record are Genua GmbH, Bundesdruckerei GmbH, mgm technology partners GmbH and secunet Security Networks AG. Broad incumbents are SGS SA, TÜV Rheinland, Utimaco Management Services, TÜV SÜD, Bureau Veritas and DEKRA.
Does SRC have an API?
No public API is recorded for SRC.
What industry is SRC in?
SRC's product category is IT Security Testing & Certification Services. Its primary akta.pro industry code is BPAHAFAO, Compliance Technology, GRC Platforms & Controls Automation Advisory, with a secondary code of BPAEAPAA, Governance, Risk & Compliance (GRC) Platforms. Its NAICS code is 54161 and its SIC code is 8742.